<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/csaf_trumpfsecokg/10</id>
  <title>Most recent entries from csaf_trumpfsecokg</title>
  <updated>2026-10-09T11:26:29.712165+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2021-033</id>
    <title>VDE-2021-033 — TRUMPF Laser GmbH: multiple products prone to codesys runtime vulnerabilities</title>
    <updated>2021-08-12T13:02:00.001000+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The TruControl laser control software (versions 1.04 to 3.0.0) uses CODESYS runtime versions affected by multiple CVEs:</p>
<p>**CVE list:**</p>
<p>- CVE-2021-29242
- CVE-2021-29241
- CVE-2019-5105
- CVE-2020-7052
- CVE-2019-9012
- CVE-2019-9010
- CVE-2019-9009
- CVE-2018-10612</p>
<p>In addition to the CVEs listed above, the affected products are also vulnerable to the following issues without a CVE ID:</p>
<p>---</p>
<p>### **CODESYS Advisory 2018-07**</p>
<p>A crafted communication request may cause an access violation in the affected CODESYS products and may result in a denial-of-service condition.</p>
<p>- **CVSS v3.0 base score:** 6.5  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H`</p>
<p>🔗 [Link to advisory](https://customers.codesys.com/index.php?eID=dumpFile&amp;t=f&amp;f=12928&amp;token=6d1dcea05a15aeef7ad48eadc64c8eca5d4f07b2&amp;download=)</p>
<p>---</p>
<p>### **CODESYS Advisory 2018-04**</p>
<p>The CODESYS runtime system allows access to files outside the restricted working directory of the controller by online services.</p>
<p>- **CVSS v3.0 base score:** 9.9  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H`</p>
<p>🔗 [Link to advisory](https://customers.codesys.com/index.php?eID=dumpFile&amp;t=f&amp;f=12925&amp;token=50e7240fa947ea215311e3db441f82152f1109b6&amp;download=)</p>
<p>---</p>
<p>### **CODESYS Advisory 2017-03**</p>
<p>A crafted request may cause an access violation in the affected CODESYS products and may result in a denial-of-service condition.</p>
<p>- **CVSS v3.0 base score:** 7.5  
- **CVSS v3.0 vector:** `CVSS:3.0/AV:N/AC:L/PR:N/…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2021-033"/>
    <published>2021-08-12T13:02:00.001000+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-016</id>
    <title>VDE-2022-016 — TRUMPF: TruTops Fab, TruTops Boost prone to vulnerability</title>
    <updated>2022-05-02T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A service function in the stated TRUMPF products is exposed without necessary authentication. Execution of this function may result in unauthorized access to, change of data or disruption of the whole service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-016"/>
    <published>2022-05-02T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-034</id>
    <title>VDE-2022-034 — TRUMPF: Products prone to Unified Automation vulnerabilities</title>
    <updated>2022-08-15T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A number of TRUMPF software tools use the OPC UA Server in C++ based OPC UA SDK by Unified Automation. The application contains several vulnerabilities, which enable an attacker to send malicious data to the application, resulting in a Denial-of-Service.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-034"/>
    <published>2022-08-15T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2022-023</id>
    <title>VDE-2022-023 — TRUMPF TruTops prone to improper access control</title>
    <updated>2022-10-17T10:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple Trumpf Products in multiple versions use default privileged Windows users and passwords. An adversary may use these accounts to remotely gain full access to the system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2022-023"/>
    <published>2022-10-17T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2023-031</id>
    <title>VDE-2023-031 — Trumpf: Multiple Products affected by WIBU Codemeter Vulnerability</title>
    <updated>2023-11-13T11:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60b) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes this vulnerability is available.Machines with a running and correctly installed mGuard hardware firewall cannot be exploited by this vulnerability if used as intended (according to the manual).</p>
<p>Update A, 2023-11-13
Removed CVE-2023-4701 because it was revoked.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2023-031"/>
    <published>2023-09-13T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-006</id>
    <title>VDE-2024-006 — TRUMPF: Oseon contains vulnerable version of OpenSSL 1.1.x</title>
    <updated>2024-01-23T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple vulnerabilities in the included versions of OpenSSL can lead to different problems, including crashes of the OpenSSL modules (leading to a Denial of Service) or leakage of plaintext. These underlying vulnerabilities can be fixed by installing a software update provided by TRUMPF.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-006"/>
    <published>2024-01-23T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-001</id>
    <title>VDE-2024-001 — TRUMPF: Multiple products contain WIBU CodeMeter vulnerabilities</title>
    <updated>2024-01-29T07:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The TRUMPF CAD/CAM software tools mentioned above use the vulnerable CodeMeter Runtime (up to version 7.60d) application from WIBU-SYSTEMS AG to manage licenses within the component TRUMPF License Expert. This CodeMeter application contains new vulnerabilities, which may enable an attacker to gain full access to the server or workstation on which the TRUMPF License Expert has been installed on. A new version of the TRUMPF License Expert which fixes these vulnerabilities is available.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-001"/>
    <published>2024-01-29T07:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-034</id>
    <title>VDE-2024-034 — Multiple TRUMPF products prone to nftables server vulnerabilities</title>
    <updated>2025-04-10T13:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>TruControl laser control software from versions 3.50.0 to 4.00.0.B use Linux kernel versions affected by CVE-2024-1086. The affected kernel vulnerability could lead to local privilege escalation.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-034"/>
    <published>2024-06-25T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2024-040</id>
    <title>VDE-2024-040 — Multiple TRUMPF products prone to regreSSHion OpenSSH server vulnerabilities</title>
    <updated>2025-04-10T13:00:00+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>TruControl laser control software prior to version 1.60.0 uses an OpenSSH server version affected by CVE-2024-6387. The affected OpenSSH Server version could potentially lead to a remote code execution.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2024-040"/>
    <published>2024-06-25T10:00:00+00:00</published>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/vde-2020-039</id>
    <title>VDE-2020-039 — TRUMPF: Multiple products prone to WIBU CodeMeter vulnerabilities</title>
    <updated>2025-05-14T12:36:39+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A number of TRUMPF CAD/CAM software tools use the CodeMeter Runtime application from WIBU-SYSTEMS AG to manage licences. This application contains a number of vulnerabilities, which enable an attacker to prevent normal operation of CodeMeter, resulting in a Denial-of-Service and potentially execute arbitrary code.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/vde-2020-039"/>
    <published>2020-10-27T10:28:00+00:00</published>
  </entry>
</feed>
